IP Library Granted Patent US 12,475,233
Granted Patent B2
US 12,475,233 · App. 18/691,837 · Granted Nov 18, 2025

Data processing method and apparatus

Inventors: Hao Zhou (Hangzhou, CN); Ruichao Liu (Hangzhou, CN); Fei Shi (Hangzhou, CN); Kan Dong (Hangzhou, CN)
Assignee: Hangzhou AliCloud Feitian Information Technology Co., Ltd.
G06F21/577G06F11/0793G06F21/74
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,475,233
App. No.
18/691,837
Granted
Nov 18, 2025
Kind
B2
Abstract

A data processing method, applied to a target device in which a Linux operating system is running. A first program is deployed in the Linux operating system. The method includes: loading a target loading and invasion machine into a first memory space of the first program, and acquiring a vulnerability repair library for the first program through the target loading and invasion machine; creating, in the first memory space, a second memory space for the target loading and invasion machine, and configuring a second runtime environment isolated from a first runtime environment of the first program; and loading the vulnerability repair library in the second memory space based on the second runtime environment, and performing a vulnerability repair on the first program by using the vulnerability repair library.

Claims (55)

1 . A data processing method, applied to a target device in which a Linux operating system is running, wherein a first program is deployed in the Linux operating system, and the method comprises:

loading a target loading and invasion machine into a first memory space of the first program, and acquiring a vulnerability repair library for the first program through the target loading and invasion machine;

creating, in the first memory space, a second memory space for the target loading and invasion machine, and configuring a second runtime environment isolated from a first runtime environment of the first program, wherein the second memory space is simply available to the target loading and invasion machine and to a program loadable by the target loading and invasion machine;

loading the vulnerability repair library in the second memory space based on the second runtime environment, and performing a vulnerability repair on the first program by using the vulnerability repair library.

2 . The method according to claim 1 , wherein before performing the vulnerability repair on the first program by using the vulnerability repair library, the method further comprises:

invading target location content in the first program according to invasion and mounting guidance information in the vulnerability repair library, and establishing a mounting relation between the target location content and the vulnerability repair library, wherein

the performing the vulnerability repair on the first program by using the vulnerability repair library comprises:

performing the vulnerability repair on the first program by performing, when the first program calls the target location content, a guidance to the vulnerability repair library according to the mounting relation.

3 . The method according to claim 2 , further comprising:

returning to an execution flow of the first program after the vulnerability repair is completed.

4 . The method according to claim 2 , wherein before invading the target location content in the first program according to the invasion and mounting guidance information in the vulnerability repair library, and establishing the mounting relation between the target location content and the vulnerability repair library, the method further comprises:

performing signature verification on the vulnerability repair library by using preset public key information;

after the signature verification is passed, rendering executions of invading the target location content in the first program according to the invasion and mounting guidance information in the vulnerability repair library and establishing the mounting relation between the target location content and the vulnerability repair library.

5 . The method according to claim 1 , wherein the target loading and invasion machine comprises: an invader for performing invasion and mounting for the first program; and a loader for creating the second memory space, configuring the second runtime environment, and loading the vulnerability repair library.

6 . The method according to claim 1 , wherein the vulnerability repair library is acquired by the target loading and invasion machine from a cloud.

7 . The method according to claim 1 , wherein the target device is an Internet of Things device, and the first program is a user mode program.

8 . A data processing apparatus, applied to a target device in which a Linux operating system is running, wherein a first program is deployed in the Linux operating system, and the apparatus comprises:

a processor, a memory, and a computer program stored in the memory and capable of running on the processor, wherein the computer program, when executed by the processor, causes the processor to:

load a target loading and invasion machine into a first memory space of the first program, and acquire a vulnerability repair library for the first program through the target loading and invasion machine;

create, in the first memory space, a second memory space for the target loading and invasion machine, and configure a second runtime environment isolated from a first runtime environment of the first program, wherein the second memory space is simply available to the target loading and invasion machine and to a program loadable by the target loading and invasion machine;

load the vulnerability repair library in the second memory space based on the second runtime environment, and perform a vulnerability repair on the first program by using the vulnerability repair library.

9 . A non-transitory computer-readable storage medium, having a computer program stored thereon, wherein the computer program, when executed by a processor, causes the processor to implement the following:

loading a target loading and invasion machine into a first memory space of a first program;

acquiring a vulnerability repair library for the first program through the target loading and invasion machine;

creating, in the first memory space, a second memory space for the target loading and invasion machine;

configuring a second runtime environment isolated from a first runtime environment of the first program, wherein the second memory space is simply available to the target loading and invasion machine and to a program loadable by the target loading and invasion machine;

loading the vulnerability repair library in the second memory space based on the second runtime environment; and

performing a vulnerability repair on the first program by using the vulnerability repair library.

10 . The apparatus according to claim 8 , wherein before performing the vulnerability repair on the first program by using the vulnerability repair library, the processor is further caused to:

invade target location content in the first program according to invasion and mounting guidance information in the vulnerability repair library;

establish a mounting relation between the target location content and the vulnerability repair library; and

perform the vulnerability repair on the first program by performing, when the first program calls the target location content, a guidance to the vulnerability repair library according to the mounting relation.

11 . The apparatus according to claim 10 , wherein the processor is further caused to:

return to an execution flow of the first program after the vulnerability repair is completed.

12 . The apparatus according to claim 10 , wherein before invading the target location content in the first program according to the invasion and mounting guidance information in the vulnerability repair library, and establishing the mounting relation between the target location content and the vulnerability repair library, the processor is further caused to:

perform signature verification on the vulnerability repair library by using preset public key information; and

after the signature verification is passed, render executions of invading the target location content in the first program according to the invasion and mounting guidance information in the vulnerability repair library and establish the mounting relation between the target location content and the vulnerability repair library.

13 . The apparatus according to claim 8 , wherein the target loading and invasion machine comprises:

an invader for performing invasion and mounting for the first program; and

a loader for creating the second memory space, configuring the second runtime environment, and loading the vulnerability repair library.

14 . The apparatus according to claim 8 , wherein the vulnerability repair library is acquired by the target loading and invasion machine from a cloud.

15 . The apparatus according to claim 8 , wherein the target device is an Internet of Things device, and the first program is a user mode program.

16 . The storage medium according to claim 9 , wherein the processor is further caused to implement the following:

invading target location content in the first program according to invasion and mounting guidance information in the vulnerability repair library;

establishing a mounting relation between the target location content and the vulnerability repair library; and

performing the vulnerability repair on the first program by performing, when the first program calls the target location content, a guidance to the vulnerability repair library according to the mounting relation.

17 . The storage medium according to claim 16 , wherein the processor is further caused to implement the following:

returning to an execution flow of the first program after the vulnerability repair is completed.

18 . The storage medium according to claim 16 , wherein before invading the target location content in the first program according to the invasion and mounting guidance information in the vulnerability repair library, and establishing the mounting relation between the target location content and the vulnerability repair library, the processor is further caused to implement the following:

performing signature verification on the vulnerability repair library by using preset public key information; and

after the signature verification is passed, rendering executions of invading the target location content in the first program according to the invasion and mounting guidance information in the vulnerability repair library and establishing the mounting relation between the target location content and the vulnerability repair library.

19 . The storage medium according to claim 9 , wherein the target loading and invasion machine comprises:

an invader for performing invasion and mounting for the first program; and

a loader for creating the second memory space, configuring the second runtime environment, and loading the vulnerability repair library.

20 . The storage medium according to claim 9 , wherein the vulnerability repair library is acquired by the target loading and invasion machine from a cloud, a target device is an Internet of Things device, and the first program is a user mode program.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 22, 2026
From: HANGZHOU ALICLOUD FEITIAN INFORMATION TECHNOLOGY CO., LTD.
To: CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PRIVATE LIMITED
Reel/Frame 075437/0941 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CORRECT THE ORDER INVENTORSARE LISTED AND TO ADD A PERIOD AT THE END OF LTD PREVIOUSLY RECORDED AT REEL: 68373 FRAME: 618. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Aug 30, 2024
From: ZHOU, HAO; LIU, RUICHAO; SHI, FEI; DONG, KAN
To: HANGZHOU ALICLOUD FEITIAN INFORMATION TECHNOLOGY CO., LTD.
Reel/Frame 068822/0146 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 22, 2024
From: ZHOU, HAO; LIU, RUICHAO; DONG, KAN; SHI, FEI
To: HANGZHOU ALICLOUD FEITIAN INFORMATION TECHNOLOGY CO., LTD
Reel/Frame 068373/0618 →
Priority Claims (1)
CN 202210138769.4 · Feb 15, 2022 · national
Continuity (1)
Related Publication 20240394380A1 · Nov 28, 2024
References Cited (18)
US 20060195745A1 · Keromytis · 2006 [cited by examiner]
US 20080083030A1 · Durham et al. · 2008 [cited by applicant]
US 20080271025A1 · Gross · 2008 [cited by examiner]
US 20100293407A1 · Locasto · 2010 [cited by examiner]
US 20170206357A1 · Gorelik · 2017 [cited by examiner]
US 20190138725A1 · Gupta · 2019 [cited by examiner]
US 20200311268A1 · Kostyushko et al. · 2020 [cited by applicant]
US 20210026947A1 · Korotaev · 2021 [cited by applicant]
CN 104424442A · 2015 [cited by applicant]
CN 10457909A · 2019 [cited by applicant]
CN 111858004A · 2020 [cited by applicant]
CN 112906008A · 2021 [cited by applicant]
CN 113158191A · 2021 [cited by examiner]
CN 114595461A · 2022 [cited by applicant]
CN 114595462A · 2022 [cited by applicant]
WO 2008008675A2 · 2008 [cited by applicant]
Notice of Allowance as received in connection with Chinese Application No. 202210138769.4, dated Jun. 13, 2024. [cited by applicant]
China National Intellectual Property Adminstration; International Search Report and Written Opinion issued in PCT App No. PCT/CN2023/074419 dated May 31, 2023, 14 pages. [cited by applicant]